Open Source Security mailing list@oss_securityDisclosure
An advisory discloses use‑after‑free and null‑pointer dereference/memory leak bugs in libfuse 3.18.0–3.18.2, specifies a patch in 3.18.2, and provides no evidence of active exploitation.
Gray Hats@the_yellow_fallPatch
Researchers identified two RCE/DoS bugs in libfuse’s io_uring transport that impact Kubernetes CSI drivers, and a patch has already been released.
CSIRT Italia@csirt_itPoC
The tweet announces the availability of a proof‑of‑concept for the Libfuse CVE‑2026‑33150 and CVE‑2026‑33179, highlighting severe impact types but providing no evidence of active exploitation, patches, or false positives.
kinneko@kinnekoDisclosure
The text announces the discovery of two critical libfuse io_uring CVEs affecting Linux and Kubernetes infrastructure, but provides no additional technical or exploit details.
CVE@CVEnewDisclosure
CVE‑2026‑33179 is a null pointer dereference and memory leak in libfuse versions 3.18.0 to 3.18.1.
Hephaestvs@Vulcanux_PoC
The tweet announces a publicly available proof‑of‑concept for CVE‑2026‑33150 and CVE‑2026‑33179 in Libfuse, detailing the associated risk types and linking to the PoC.